To audit AI agents, treat each agent as two things at once: a user with credentials, and a program that changes. Then test nine areas: whether the company knows what agents it has and who owns each, what each is permitted to do, how changes are controlled, whether actions are logged and can be replayed, where a human must approve, what data the agent reaches, how incidents are handled, what the vendor contract says, and whether anyone monitors for drift.
This programme is for an internal audit of a company that is deploying AI agents in its own operations: an agent that raises purchase orders, answers customers, reconciles accounts or releases payments. It is written for heads of internal audit and CA firms doing internal audit in India. If the question is instead whether your audit team should use agents for its own work, see agentic AI in internal audit.
Start here if you want the working files:
| Need | Use this |
|---|---|
| An editable working paper: AI inventory, ownership, control tests and evidence request list | AI Governance Internal Audit Workpaper |
| The audit function's own policy on AI use | Internal Audit AI Strategy Template |
| Fraud risks that AI creates or accelerates, as a checklist | AI-enabled fraud internal audit checklist |
| Due diligence on the vendor supplying the agent | AI vendor due diligence checklist |
Why now: what was reported in September 2026
Four things published in the last six weeks explain why this belongs in an FY 2026-27 plan.
Companies are running agents their governance was not written for. EY's US AI Risk and Governance Survey, published on 15 September 2026, covered 202 senior AI decision-makers at US listed companies with at least US$1 billion in revenue. According to EY, among organisations using agentic AI, 49% said their governance framework has not been specifically updated for it; 26% of respondents said they cannot detect unauthorised AI agents operating internally; and 47% said their organisation had bypassed its AI governance process for an urgent deployment.
Audit coverage is thin. The IIA's Internal Audit Foundation reported on 15 September 2026, from a survey of 3,285 audit leaders in 132 countries and locations, that 58% rate digital disruption, including AI, as a top-five risk, but only 23% rated its risk governance as managed or optimised and 11% reported full audit coverage.
A policy on paper is not a control. Forvis Mazars argued on 31 August 2026 that companies have AI governance frameworks in writing while staff use unapproved tools outside sanctioned workflows, and recommended an inventory, an assessment against the five COSO components, and bringing internal audit into the risk assessment.
Agents have been reported acting outside their task. Press reports in September described an AI developer disclosing incidents in which its own agents searched for exposed access keys and reached websites without authorisation (Tekedia, 18 September; Security Boulevard, 26 September). We read the press reports, not the company's own disclosures.
These surveys are of large and mostly US companies. For an Indian company the percentages do not transfer, but the questions do.
What makes an agent different to audit
An internal auditor already knows how to audit a user and how to audit a system. An agent combines the two, with three features that change the tests.
- It chooses its own steps. Two runs of the same task may take different routes. Testing one transaction's path tells you less than it does for a fixed workflow.
- Its "program" is partly words. The instructions that govern it (often called the prompt), the list of tools it may call, and the underlying AI model can each be changed, sometimes by the vendor, and each change alters behaviour.
- It acts at machine speed with human-level access. An employee who misreads a rule makes a few errors a day. An agent repeats the error on every item until somebody notices.
For auditing AI models that produce numbers in the financial statements, such as credit scoring or provisioning, see auditing AI systems: a framework for CA firms. This programme is about agents that act.
Where this sits in the audit plan
Under Rule 13 of the Companies (Accounts) Rules, 2014, the audit committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit. A review of AI agents is a scope item for them to approve. Two practical routes:
- A standalone review where agents already post, approve or pay.
- An add-on to the IT general controls review, covering areas 1 to 4 below, where agents are few or still in pilot. The ITGC internal audit checklist is the base.
The audit programme: nine areas
| # | Area | Risk | Control to look for | Test | Evidence |
|---|---|---|---|---|---|
| 1 | Inventory and ownership | Agents run that nobody has listed; no one answers for what an agent does | A register of every agent with purpose, business owner, technical owner, systems touched and status; a rule that no agent goes live unregistered | Compare the register with service accounts, API keys and automation tools actually in use; ask three departments what they run | Agent register; list of service accounts and keys from IT; approval record for each agent |
| 2 | Permissions and credentials | The agent can do more than its task needs; it shares a person's login, so actions cannot be told apart | Each agent has its own named account, least access, no shared passwords or keys, limits on value and volume; access reviewed periodically | For a selected agent, list what its account can do and compare with its approved purpose; attempt (in test) an action outside the purpose | Role and access listing; key inventory; last access review; test result |
| 3 | Change control over prompts, tools and models | Behaviour changes without approval or testing, including when the vendor updates the model | Instructions, tool lists and model versions are versioned; changes are requested, tested, approved and can be rolled back; vendor model changes are notified | Take the current instructions and trace each difference from the last approved version to a change record; check test results exist | Version history; change tickets; test results; vendor change notices |
| 4 | Logging and replay | Nobody can reconstruct what the agent did or why | Every action is logged with time, input, tool called, output and the agent's identity; logs are kept where the agent cannot alter them, for a defined period | Pick ten completed tasks and rebuild each from the log alone; confirm the log matches entries in the business system | Log extracts; retention setting; reconciliation of log to system entries |
| 5 | Human approval points | The agent completes actions that policy says need a person; or the approval is a click with nothing reviewed | Defined thresholds above which the agent must stop and ask; the approver sees the underlying records; the delegation of authority names the agent's limits | Select actions above threshold and confirm a human approved each before it took effect; check what the approver was shown and how long approvals took | Delegation of authority; approval trail; sample of approver screens |
| 6 | Data access and personal data | Personal or confidential data goes to the agent or its vendor without a lawful basis, or is retained | Data the agent may read is defined and minimised; personal data is masked where the task allows; data location and retention are known | Trace one task's data from source to vendor and back; compare with the approved data list | Data flow map; vendor data terms; masking configuration |
| 7 | Incident handling | An agent error is fixed quietly, not recorded, and recurs | A definition of an agent incident; a way to stop the agent at once; a log of incidents with cause and fix; reporting to the risk or audit committee | Ask for the incident log; test the stop switch; look for corrections in the business system that have no matching incident | Incident register; stop-switch test record; committee papers |
| 8 | Third-party and vendor terms | The contract leaves the company with liability, no audit rights and no notice of changes | Contract covers data use, sub-processors, change notice, audit or assurance reports, liability and exit | Read the contract against the list; obtain the vendor's latest assurance report and check its scope covers the service used | Contract; assurance report; exit plan |
| 9 | Monitoring for drift | Output quality declines, or the agent stops following a rule, and nobody measures it | Periodic re-testing against a fixed set of cases; business rules checked by a separate rule engine, not only stated in the instructions; exception and override rates tracked | Re-run the fixed cases and compare with the last result; check that key rules are enforced outside the agent | Test set and results over time; rule engine configuration; exception trend |
Area 8 is covered in depth in the AI vendor due diligence checklist, and the working paper tool holds the inventory and evidence request sheets, so neither is repeated here.
A note on drift and long-running agents
A contributed article in VentureBeat on 13 September 2026 argues that an agent on a long, multi-step workflow can lose track of constraints given at the start as its working context fills, and that a larger context does not solve this. It is a practitioner's argument, not a measured study, so treat it as a risk to test for. The control it points to is the one in area 9: rules that matter (a payment limit, an approval requirement, a restricted vendor list) should be enforced by a separate check on the agent's output, and re-validated at checkpoints in a long task. The audit test is direct: find a rule stated only in the instructions, and ask what stops the action if the agent ignores it.
A note on ISO/IEC 42001
ISO/IEC 42001 is the AI management system standard. KPMG Canada, announcing its own certification on 2 September 2026, described it as providing "a framework for governing the development, deployment and use of AI systems through clear accountability, risk management, oversight, monitoring and continuous improvement". It is a voluntary standard, and a certificate held by a vendor tells you about the vendor's management system, not about how your company has configured its agent. Obtain the standard itself before testing against it; this programme does not restate its requirements.
Worked example: testing area 2 on an accounts payable agent
The figures are illustrative. A company uses an agent to match supplier invoices to purchase orders and goods receipts and to propose payments. The approved purpose says: "match and propose; payments above ₹2 lakh need approval by the accounts payable lead."
| Step | What internal audit did | What it found |
|---|---|---|
| 1 | Obtained the access listing for the agent's account | The account could create payment proposals and also edit vendor master records |
| 2 | Compared with the approved purpose | Editing vendor master records was not in the purpose |
| 3 | Queried the vendor master change log for changes made by the agent's account in the half-year | 14 changes, all to vendor email addresses; none to bank details |
| 4 | Checked payments proposed by the agent above ₹2 lakh | 1,126 proposals; 1,119 approved by the accounts payable lead before release; 7 released under a "bulk approve" action covering 7 invoices worth ₹31.5 lakh in one click |
| 5 | Asked what the approver saw on bulk approval | A total and a count, not the invoices |
The observation, in five parts. Condition: the agent's account holds vendor master edit rights beyond its approved purpose, and bulk approval lets payments above the threshold be released without the approver seeing the invoices. Criteria: the approved purpose document and the delegation of authority. Cause: the account was copied from an accounts payable clerk's role at set-up. Effect: an agent error or a manipulated instruction could change vendor details and propose a payment within one account; seven payments were approved without sight of documents. Recommendation: remove master-data rights from the agent's account, show invoice-level detail on bulk approval or disable it above the threshold, and add the agent's account to the periodic access review.
Nothing here is specific to AI in technique. The auditor's existing tests apply once the agent is treated as a user.
The India lens
Law. We know of no Indian statute specific to AI agents. Test against the law that already applies: the Companies Act framework for internal audit and internal financial controls, the Digital Personal Data Protection Act, 2023 for personal data (the duties stay with the company that decides how the data is used, even when a vendor's agent processes it; see DPDP for CA firms), sector rules for regulated entities, and the company's own contracts and policies.
Internal financial controls. Where an agent initiates, approves or records transactions, it is part of the control environment that the statutory auditor reports on under Section 143(3)(i). Tell the statutory auditor what agents are in the finance processes.
Standards. ICAI lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026. Check the compendium before citing a standard number in the report.
Smaller companies. A company with one agent and no AI policy can still be tested on areas 1, 2, 4 and 5. Those four tell the audit committee most of what it needs.
For ongoing checks rather than a periodic review, the rule-engine idea in area 9 is the same one behind transaction monitoring; platforms such as CORAA's internal audit product run fixed rules across every transaction, whoever or whatever posted it.
How to audit AI agents: FAQ
How do you audit an AI agent?
Audit an AI agent as both a user and a changing program. Confirm it is on a register with an owner, compare what its account can do with its approved purpose, trace changes to its instructions and model to approvals, rebuild a sample of its tasks from the log, and check that human approvals above the threshold really happened.
What are the key controls over agentic AI in 2026?
The key controls are an agent inventory with named owners, a separate least-privilege account for each agent, change control over instructions, tools and models, tamper-resistant logs, human approval above defined thresholds, a tested way to stop the agent, and periodic re-testing for drift.
What evidence should internal audit ask for in an AI agent review?
Ask for the agent register, the access listing for each agent's account, the version history of its instructions and model, action logs for a sample of tasks, the approval trail for actions above threshold, the incident log, and the vendor contract and assurance report.
Is there an AI governance internal audit checklist?
Yes. The nine-area table above works as a checklist, and the AI Governance Internal Audit Workpaper provides the inventory, control test and evidence request sheets in an editable form.
Is ISO/IEC 42001 mandatory in India?
We know of no Indian law that makes ISO/IEC 42001 mandatory. It is a voluntary AI management system standard that a company or vendor may choose to be certified against.
Related CORAA resources
- AI Governance Internal Audit Workpaper
- Internal Audit AI Strategy Template
- AI-enabled fraud internal audit checklist
- AI vendor due diligence checklist for internal audit
- Auditing AI systems: a framework for CA firms
- AI in internal audit: October 2026 update
Sources
Pages read on 1 October 2026.
- EY, "AI governance has entered its next phase: closing the confidence gap", 15 September 2026 — https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap
- EY (PR Newswire), "EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap", 15 September 2026 — https://www.prnewswire.com/news-releases/ey-survey-finds-that-autonomous-ai-implementation-outpaces-oversight-yielding-an-ai-governance-gap-302878162.html
- The Institute of Internal Auditors, "New Survey from The IIA's Foundation Finds Digital Disruption and Geopolitical Risks Surge as Organizations Face an Increasingly Interconnected Global Risk Landscape", 15 September 2026 — https://www.theiia.org/en/content/communications/press-releases/2026/september/new-survey-from-the-iias-foundation-finds-digital-disruption-and-geopolitical-risks-surge-as-organizations-face-an-increasingly-interconnected-global-risk-landscape/
- Forvis Mazars, "Closing the Gap Between AI Governance & Internal Controls", 31 August 2026 — https://www.forvismazars.us/forsights/2026/08/closing-the-gap-between-ai-governance-internal-controls
- VentureBeat, "Long-running AI agents quietly drop compliance rules, and bigger context windows won't fix it", 13 September 2026 — https://venturebeat.com/orchestration/long-running-ai-agents-quietly-drop-compliance-rules-and-bigger-context-windows-wont-fix-it
- Tekedia, "OpenAI Discloses Six New AI Misalignment Incidents As Models Conceal Errors And Probe System Boundaries", 18 September 2026 — https://www.tekedia.com/openai-discloses-six-new-ai-misalignment-incidents-as-models-conceal-errors-and-probe-system-boundaries/
- Security Boulevard, "OpenAI Discloses Unauthorized AI Agent Activity Across U.S., Australian Government Websites", 26 September 2026 — https://securityboulevard.com/2026/09/openai-discloses-unauthorized-ai-agent-activity-across-u-s-australian-government-websites/
- KPMG Canada (CNW), "KPMG Canada achieves ISO 42001 certification as organizations seek greater trust and governance in AI", 2 September 2026 — https://www.newswire.ca/news-releases/kpmg-canada-achieves-iso-42001-certification-as-organizations-seek-greater-trust-and-governance-in-ai-853166590.html
- ICAI Internal Audit Standards Board, "Compendium of Standards on Internal Audit" — https://internalaudit.icai.org/compendium-of-standard/
- Companies Act, 2013, Sections 138 and 143, and Companies (Accounts) Rules, 2014, Rule 13 — https://www.mca.gov.in/content/mca/global/en/acts-rules/companies-act/companies-act-2013.html